Skip to content

2026 04 26 systems capability debt citizen development empirical evidence

github-actions[bot] edited this page Apr 30, 2026 · 2 revisions

Systems capability debt as the root cause of citizen development: empirical evidence and effective governance architectures

Research Question

What empirical evidence exists that systems capability debt, the accumulated gap between what people need from their systems and what those systems deliver across integration, functionality, data access, data quality, data migration, User Experience (UX), and timeliness dimensions, is the root cause of citizen development sprawl in regulated financial services organisations; what is its quantified operational risk cost; and what governance architectures have demonstrably reduced citizen development sprawl without suppressing legitimate automation demand?

Scope

In scope:

  • Empirical studies quantifying the operational risk cost of systems capability debt across its forms: integration gaps, shadow data proliferation, ungoverned automation, functionality workarounds
  • Evidence distinguishing causal driver of citizen development, capability gap versus low-code tooling preference
  • Governance architectures combining licensing gates, environment strategy, Data Loss Prevention (DLP) policy enforcement, deployment pipelines, and engineering investment
  • Relationship between systems capability maturity metrics, Application Programming Interface (API) coverage, event-driven architecture adoption, data contract completeness, data classification coverage, and access control completeness, and the safe permissible scope of agentic Artificial Intelligence (AI)
  • A decision framework for distinguishing genuine AI use cases from automation compensating for absent capability
  • Organisational dynamics of systems capability debt accumulation and what governance structures reverse the pattern
  • Evidence from banking, financial services, or analogous regulated industries
  • Incident databases, regulatory enforcement actions, near-miss reports, and academic studies
  • Context: a New Zealand Crown-owned bank subject to Reserve Bank of New Zealand (RBNZ) oversight, NZ Privacy Act 2020, and Payment Card Industry Data Security Standard (PCI-DSS), operating Microsoft 365 with Copilot and Copilot Studio and building agentic capability on Amazon Web Services (AWS) Bedrock

Out of scope:

  • Theoretical novelty of the synthesis argument, covered by the companion Q1 item
  • Jurisdiction-specific regulatory framework analysis, covered by the companion Q3 item
  • Technical implementation details of specific governance tools
  • Non-regulated industries unless the evidence is directly applicable to financial services

Constraints:

  • Prioritise empirical sources: incident databases, regulatory enforcement actions, academic studies with measured outcomes; conceptual frameworks are acceptable only if supported by empirical illustration
  • Quantified evidence, financial cost, risk exposure, or incident frequency, is strongly preferred over qualitative accounts
  • Governance architecture evidence must include measured outcomes, not just claimed design intent
  • Sources must be assessable for generalisability to a New Zealand banking context

Context

  • [inference; source: https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] The decision problem is whether a regulated bank should treat citizen development sprawl primarily as a tool-governance problem or as evidence that core systems, data, and delivery workflows are failing to meet operational demand quickly enough.
  • [fact; source: https://www.privacy.org.nz/privacy-principles/; https://www.legislation.govt.nz/act/public/2020/0031/latest/LMS23223.html; https://www.pcisecuritystandards.org/document_library/; https://www.rbnz.govt.nz/-/media/project/sites/rbnz/files/regulation-and-supervision/thematic-reviews/rbnz-risk-management-thematic-report.pdf] The New Zealand context is materially relevant because the Privacy Act 2020 imposes storage, accuracy, use, and disclosure duties for personal information, PCI-DSS remains the governing standard for payment-card environments, and RBNZ frames effective risk management as central to reducing operational failures, financial losses, and systemic disruption.
  • [fact; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://docs.aws.amazon.com/bedrock/latest/userguide/security.html] The bank's current platform context also matters because Copilot Studio and Amazon Web Services (AWS) Bedrock both assume explicit data governance, access control, and environment-level guardrails rather than unconstrained end-user autonomy.

Approach

  1. Operational risk cost quantification - Search incident databases, Operational Riskdata eXchange Association (ORX), internal bank loss data publications, regulatory enforcement actions, academic literature, and industry reports for quantified costs of integration gaps, shadow data, ungoverned automation, and functionality workarounds; express findings as financial values or proportions of operational risk exposure where possible.
  2. Causal linkage evidence - Review empirical studies on citizen development adoption drivers; specifically search for research that distinguishes workaround for capability gap from preference for low-code tooling and quantifies their relative contribution; assess whether any study establishes causal rather than merely correlational links.
  3. Governance architecture case studies - Locate documented case studies of organisations that have reduced citizen development sprawl using combinations of licensing gates, environment strategy, DLP enforcement, deployment pipelines, and engineering investment; assess measured outcomes and sustainability.
  4. Capability maturity and agentic AI scope - Review literature and practitioner frameworks linking systems capability maturity, API coverage, event-driven architecture, data contracts, data classification, and access control, to the safe permissible scope of autonomous agents; assess whether any existing framework provides a readiness threshold model.
  5. AI use case versus capability gap distinction - Search for decision frameworks that distinguish genuine AI reasoning tasks from automation compensating for absent engineering; assess usability by non-technical decision-makers and defensibility in a risk committee context.
  6. Organisational dynamics of debt accumulation - Review organisational behaviour and Information Technology (IT) governance literature on why organisations consistently defer engineering remediation; identify governance and incentive structures that have successfully reversed the pattern; assess applicability to a regulated bank context.

Sources

Related


Research Skill Output

(Full output from running the research skill - retained verbatim in the completed item. Sections 0-5 are the investigation, and section 6 seeds the Findings section below.)

§0 Initialise

  • [fact; source: https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406).html] Research question restated: how strong is the empirical case that systems capability debt is the main causal driver of citizen development sprawl in regulated financial services, what measurable operational-risk costs attach to that workaround estate, and which governance architectures reduce the sprawl without suppressing legitimate automation demand?
  • [fact; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance] Scope confirmed: this investigation covers causal evidence, quantified costs, governance case evidence, agentic-readiness implications, and a practical distinction between genuine AI use cases and automation that merely compensates for absent engineering capability.
  • [fact; source: https://www.theguardian.com/business/2021/dec/20/standard-chartered-fined-bank-of-england-pra; https://www.nysd.uscourts.gov/sites/default/files/2021-02/20cv6539%20Citibank%20Opinion.pdf; https://www.govinfo.gov/content/pkg/CHRG-113shrg80222/pdf/CHRG-113shrg80222.pdf] Constraint confirmed: public, citable incident and regulatory sources can quantify adjacent operational-risk costs, but the public record is stronger on spreadsheet, data, and manual-control failures than on clean before-and-after measurements of citizen-development sprawl itself.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-use-case-routing-frameworks.html] Prior completed repository work already established low-code governance prerequisites, the broader systems-capability-debt causal chain, and intake-routing logic, so this item concentrates on empirical support, quantified cost, and documented governance outcomes rather than first-principles novelty.

§1 Question Decomposition

  • Root question: Does empirical evidence support the claim that systems capability debt is the dominant cause of citizen development sprawl, and what governance response works in regulated settings?
  • A. Causal-driver evidence
    • A1. What does Shadow IT and Business-managed Information Technology (Business-managed IT) literature identify as the main causes of workaround technology adoption?
    • A2. What does low-code and no-code adoption research say about speed, cost, talent scarcity, unmet demand, and tool preference?
    • A3. Does any evidence support a stronger claim than correlation, namely that capability gaps generate the demand that citizen-development tools absorb?
  • B. Quantified operational-risk cost
    • B1. What public evidence quantifies losses tied to poor data quality, spreadsheet workarounds, legacy processing, or manual-control failure?
    • B2. What banking or banking-adjacent enforcement actions quantify the cost of weak controls around workaround estates?
    • B3. How much of the quantified cost can be attributed directly to citizen development versus adjacent manifestations of systems capability debt?
  • C. Governance architectures
    • C1. What governance patterns do Microsoft and analogous programs prescribe for large-scale citizen development?
    • C2. Which public case studies show measured outcomes from those patterns?
    • C3. Do those patterns combine control with an explicit fast path for legitimate automation demand?
  • D. Capability maturity and agentic scope
    • D1. Which frameworks tie safe autonomous scope to data quality, access control, approved connectors, feedback loops, and internal platforms?
    • D2. Does any public framework provide a threshold model that a risk committee could use directly?
  • E. Decision framework
    • E1. Can the evidence support a practical distinction between genuine AI reasoning use cases and automation demand caused by missing capability?
    • E2. What uncertainties remain where the evidence is weak or indirect?

§2 Investigation

Source access and replacement notes

  • Access note: https://orx.org/research/ returned 404.
  • Access note: https://www.gartner.com/en/information-technology/topics/citizen-development returned 403.
  • Access note: https://www.forrester.com/research/low-code-no-code/ returned 404.
  • Access note: https://www.rbnz.govt.nz/regulation-and-supervision/oversight-of-banks returned 403.
  • Access note: https://www.privacy.org.nz/privacy-act-2020/ returned 404.
  • Access note: direct PCI-DSS and some RBNZ PDFs returned 403 from this runtime; accessible landing pages, search-discovered official URLs, and mirrored summaries were used instead where needed.
  • Failed primary-source search record: query "systems capability debt" literature across web search and repository discovery; outcome: no established published canon using that exact term.
  • Failed primary-source search record: query "agentic AI readiness threshold" data classification access control API coverage and query "autonomous agent readiness model" enterprise; outcome: no public quantitative threshold model found.
  • Failed primary-source search record: query "citizen development" banking case study reduction sprawl measured before after; outcome: no public bank case with explicit before-and-after sprawl-count reduction was found.

A. What the causal-driver literature shows

  • [fact; source: https://jitm.ubalt.edu/XXX-4/article1.pdf] The 2019 practitioner-perceptions study of 29 chief information officers and senior IT managers finds that lack of business-IT alignment appears in 48% of interviews, that Information Technology organisation slowness is treated as the primary motivator for Shadow IT and Business-managed IT, and that interviewees describe system modernisation, more agility, and better alignment as the main routes for reducing those behaviours.
  • [fact; source: https://jitm.ubalt.edu/XXX-4/article1.pdf] The same study reports that 76% of participants aimed to improve IT agility and 90% discussed system modernisation as part of reducing workaround demand, which is direct practitioner evidence that respondents see capability remediation, not only restriction, as the durable control response.
  • [fact; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf] The 2019 systematic literature review states that slow responsiveness, long development times, lengthy procurement processes, and shortcomings of existing IT systems foster Shadow IT and that Shadow IT and Business-managed IT use can be reduced if existing system shortcomings are addressed to fulfill unmet needs.
  • [fact; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf] The same review also records productivity gain as a recurring benefit of Shadow IT and Business-managed IT, which explains why pure prohibition is unstable when sanctioned systems remain slower or less fit for purpose than the workaround.
  • [fact; source: https://d-nb.info/1270139835/34] The 2022 low-code adoption review says organisations face strong pressure to digitise rapidly, face a significant shortage of skilled IT developers, and use low-code platforms to reduce hand-written code, reduce time to market, and increase productivity, while also warning that low-code can induce security risks, shadow IT, and scaling and maintenance problems.
  • [fact; source: https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406).html] The 2023 practitioner study on low-code adoption identifies 12 drivers and 19 inhibitors across 17 experts, which supports a multifactor picture where speed, cost, and delivery pressure matter, but not a simple preference-only story about low-code tools.
  • [fact; source: https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6] The 2025 systematic review identifies 40 primary studies on low-code and no-code adoption and citizen development, confirming that the field is broad enough to support synthesis but still fragmented enough that direct bank-specific causal quantification remains sparse.
  • [inference; source: https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://d-nb.info/1270139835/34; https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406).html] Taken together, the empirical literature supports a strong claim that capability gaps, slowness, misalignment, and unmet demand are the dominant recurring drivers of citizen-development behaviour, while low-code tooling acts mainly as the mechanism that makes the workaround estate easier to build once the demand already exists.
  • [inference; source: https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf] The evidence does not support a monocausal statement that systems capability debt is the only cause of citizen development sprawl, but it does support the narrower and defensible claim that it is the strongest recurring root driver in the literature on workaround technology adoption.

B. What can be quantified about operational-risk cost

  • [fact; source: https://www.ibm.com/think/insights/cost-of-poor-data-quality] International Business Machines (IBM) reports that more than one quarter of organisations estimate annual losses above United States dollar (USD) 5 million from poor data quality and that 7% report annual losses of USD 25 million or more, which is public quantitative evidence for one major dimension of systems capability debt.
  • [fact; source: https://www.fdic.gov/media/168191] The FDIC working paper uses supervisory data covering 434,714 operational loss events and finds that higher losses from innovation are traceable to external fraud, failures in obligations to clients, and faulty product design, with payment technologies and retail and commercial banking especially problematic.
  • [fact; source: https://www.federalreserve.gov/econres/notes/feds-notes/operational-risk-regulation-forward-looking-and-sensitive-to-current-risks-20180521.html] The Federal Reserve note states that operational failures and fraud produced major losses to large US banks over the prior fifteen years and that Advanced Measurement Approach operational-risk capital represented 29% of risk-weighted assets for the largest advanced-approach banks as of June 2017.
  • [fact; source: https://www.bankofengland.co.uk/-/media/boe/files/prudential-regulation/regulatory-action/final-notice-from-pra-to-standard-chartered-bank.pdf; https://www.theguardian.com/business/2021/dec/20/standard-chartered-fined-bank-of-england-pra] The Prudential Regulation Authority (PRA) fined Standard Chartered British pound sterling (GBP) 46.55 million after repeated liquidity-reporting failures, including a spreadsheet cell, Line 49, that showed a positive value of around USD 10 billion where a zero or negative figure was expected, creating a USD 7.9 billion to USD 10 billion overstatement of dollar liquidity position.
  • [fact; source: https://www.nysd.uscourts.gov/sites/default/files/2021-02/20cv6539%20Citibank%20Opinion.pdf] The Citibank Revlon opinion records that Citibank intended to send a USD 7.8 million interest payment but instead transferred approximately USD 893 million because the operators failed to select the correct processing fields in the legacy Flexcube workflow, and the principal amount went out the door.
  • [fact; source: https://www.govinfo.gov/content/pkg/CHRG-113shrg80222/pdf/CHRG-113shrg80222.pdf] The United States (US) Senate record on the JPMorgan whale trades states that losses reached USD 6.2 billion and describes the Value at Risk workflow as a chain of Excel spreadsheets completed manually by copying and pasting data from one sheet to another.
  • [fact; source: https://www.trendfollowing.com/whitepaper/jpm.pdf] The same JPMorgan record says the spreadsheet calculating relative changes in hazard rates divided by the sum instead of the average, likely muting volatility by roughly a factor of two and lowering the Value at Risk estimate.
  • [inference; source: https://www.ibm.com/think/insights/cost-of-poor-data-quality; https://www.bankofengland.co.uk/-/media/boe/files/prudential-regulation/regulatory-action/final-notice-from-pra-to-standard-chartered-bank.pdf; https://www.nysd.uscourts.gov/sites/default/files/2021-02/20cv6539%20Citibank%20Opinion.pdf; https://www.govinfo.gov/content/pkg/CHRG-113shrg80222/pdf/CHRG-113shrg80222.pdf] Public quantified cost evidence is materially stronger for adjacent manifestations of systems capability debt, poor data quality, spreadsheet control failures, manual processing, and legacy workflow brittleness, than for citizen development labelled explicitly as such, but those manifestations are the operational-risk channels through which citizen-development sprawl becomes expensive.
  • [inference; source: https://www.fdic.gov/media/168191; https://www.federalreserve.gov/econres/notes/feds-notes/operational-risk-regulation-forward-looking-and-sensitive-to-current-risks-20180521.html] The evidence supports a quantified operational-risk conclusion of materiality, not a precise universal average cost of citizen-development sprawl, because banking loss datasets are sensitive and usually anonymised, while public evidence overrepresents the largest control failures.

C. What governance architectures show

  • [fact; source: https://learn.microsoft.com/en-us/power-platform/guidance/adoption/common-vision/establish-coe] Microsoft's Center of Excellence guidance prescribes a governance architecture with clear roles, use-case evaluation, environment strategy, maintenance and cleanup, data governance, connector governance, metrics, and a decision matrix for platform and license selection.
  • [fact; source: https://learn.microsoft.com/en-us/power-platform/guidance/adoption/govern-at-scale; https://learn.microsoft.com/en-us/power-platform/admin/governance-considerations] Microsoft's scale guidance adds maturity staging, connector management, environment management, solution-development standards, security protocols, centralized or federated delivery models, and automated request processes for environments and connectors.
  • [fact; source: https://learn.microsoft.com/en-us/power-platform/guidance/coe/overview; https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention] The Power Platform and Copilot Studio governance stack includes telemetry dashboards, orphaned-app detection, environment routing, maker welcome messages, real-time DLP enforcement over knowledge sources and HTTP calls, audit logging, authentication control, and connector grouping into business, non-business, and blocked categories.
  • [fact; source: https://www.microsoft.com/en/customers/story/25909-heineken-microsoft-copilot-studio] HEINEKEN reports more than 7,500 makers, more than 10,000 apps, more than 42,000 flows, more than 8,000 environments, a five-person product team, and 3.1 million hours of increased productivity under a three-tier environment model with automatic routing, 20-user limits in personal environments, shared production environments, enterprise production environments, Managed Environments, solution checking, and pipelines.
  • [fact; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://cloud.google.com/resources/content/2025-dora-ai-capabilities-model-report] DevOps Research and Assessment (DORA) finds that internal platforms are crucial for scaling AI successfully, that 90% of organisations have adopted at least one platform, and that 76% now have dedicated platform teams, while also warning that AI adoption worsens stability when robust control systems and feedback loops are absent.
  • [inference; source: https://www.microsoft.com/en/customers/story/25909-heineken-microsoft-copilot-studio; https://learn.microsoft.com/en-us/power-platform/guidance/adoption/common-vision/establish-coe; https://learn.microsoft.com/en-us/power-platform/guidance/adoption/govern-at-scale] The strongest public example of sprawl reduction without demand suppression is not a blanket ban but a tiered operating model: low-friction personal environments for low-risk work, automatic promotion triggers when adoption grows, shared production lanes, enterprise lanes with stronger oversight, and a central telemetry and policy plane.
  • [inference; source: https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://learn.microsoft.com/en-us/power-platform/guidance/coe/overview] This architecture matches the workaround literature because it governs the visible estate while also improving sanctioned delivery speed, which is precisely the combination the Shadow IT literature identifies as necessary to reduce demand for unsanctioned workarounds.

D. Capability maturity and agentic scope

  • [fact; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook] National Institute of Standards and Technology (NIST) says AI risk management should be continuous across the lifecycle, should reflect organisational risk tolerance, and after governance structures exist, should begin with mapping context, intended use, and impacts before measurement and management.
  • [fact; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://docs.aws.amazon.com/bedrock/latest/userguide/security.html] Amazon Web Services (AWS) states that agentic AI acts autonomously at machine speed with real-world consequences, that least privilege and deterministic external controls must come before trust in the agent's own reasoning loop, and that Bedrock security remains a shared-responsibility problem.
  • [fact; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention] Copilot Studio governance assumes that safe scope depends on enforceable authentication choices, controlled knowledge sources, blocked or grouped connectors, channel restrictions, trigger restrictions, and environment policy, not on maker discretion alone.
  • [fact; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] DORA says AI accelerates software delivery but exposes downstream weaknesses when automated testing, version control, feedback loops, and loosely coupled architectures are weak.
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] The convergence across NIST, AWS, Microsoft, and DORA is that safe autonomous scope expands only after data classification, access control, approved interfaces, telemetry, testing, and platform guardrails are already present, which means capability maturity is a precondition for agent breadth.
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] No public framework in the reviewed material provides a simple threshold model such as a numeric readiness score above which broad agentic autonomy is safe, so risk committees still need a qualitative control checklist rather than a single pass or fail number.

E. Distinguishing genuine AI use cases from capability-gap compensation

  • [fact; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] DORA and NIST both frame successful AI deployment as a problem of fitting the use case to user need, organisational workflow, controls, and context rather than beginning with the tool.
  • [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://learn.microsoft.com/en-us/power-platform/guidance/adoption/common-vision/establish-coe; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention] A practical decision rule follows: if the proposed AI system's main value disappears once the organisation supplies clean data, reliable integration, timely workflow, and sanctioned automation, then the use case is primarily compensating for missing capability rather than using AI for irreducibly probabilistic reasoning.
  • [inference; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] Conversely, use cases that still create value after core capability remediation, such as triage over unstructured inputs, summarisation across large document sets, or bounded recommendation within controlled interfaces, are more likely to be genuine AI use cases.
  • [assumption; source: https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://www.microsoft.com/en/customers/story/25909-heineken-microsoft-copilot-studio] The Shadow IT, Business-managed IT, and large-enterprise Power Platform evidence is treated as directionally applicable to regulated banking citizen development. Justification: public bank-specific citizen-development case evidence is scarce, but the underlying organisational mechanisms, unmet demand, workaround creation, policy evasion, and tiered-governance responses, are platform and operating-model patterns rather than sector-unique technical properties.

§3 Reasoning

  • [fact; source: https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf] The strongest empirical basis for the causal claim comes from Shadow IT and Business-managed IT studies because they explicitly examine why business units procure or build unsanctioned or semi-sanctioned technology when official IT channels are too slow or too misaligned.
  • [fact; source: https://d-nb.info/1270139835/34; https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406).html; https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6] Low-code adoption research widens the picture by showing that faster and cheaper delivery is attractive, but it does not overturn the workaround evidence because speed pressure and talent scarcity are themselves forms of capability shortfall at the organisational level.
  • [inference; source: https://www.ibm.com/think/insights/cost-of-poor-data-quality; https://www.bankofengland.co.uk/-/media/boe/files/prudential-regulation/regulatory-action/final-notice-from-pra-to-standard-chartered-bank.pdf; https://www.nysd.uscourts.gov/sites/default/files/2021-02/20cv6539%20Citibank%20Opinion.pdf; https://www.govinfo.gov/content/pkg/CHRG-113shrg80222/pdf/CHRG-113shrg80222.pdf] Quantified cost is best handled by tracing the operational-risk channels that citizen development and workaround estates create, data quality failure, spreadsheet control failure, legacy workflow brittleness, and manual processing error, because public sources rarely tag the final loss event as citizen development even when the mechanism is the same.
  • [inference; source: https://www.microsoft.com/en/customers/story/25909-heineken-microsoft-copilot-studio; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://learn.microsoft.com/en-us/power-platform/guidance/adoption/common-vision/establish-coe] The governance answer is therefore a combined architecture, central telemetry and policy enforcement plus a fast sanctioned delivery path, because either element alone fails: restriction alone drives workaround behaviour underground, while enablement alone scales uncontrolled risk.
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention] The agentic-AI implication is sequential: unresolved capability debt narrows the safe scope of autonomous systems because it removes reliable data, clear permissions, and deterministic boundaries that agent governance frameworks assume.

§4 Consistency Check

  • [fact; source: https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf] There is no contradiction between the practitioner and literature findings on workaround causation because both identify IT slowness, misalignment, and system shortcomings as core drivers and both identify capability remediation as part of the governance answer.
  • [fact; source: https://d-nb.info/1270139835/34; https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406).html] There is also no contradiction between low-code adoption research and the workaround literature because low-code studies explain why the enabling tool is attractive, while workaround studies explain why the demand arises in the first place.
  • [inference; source: https://www.ibm.com/think/insights/cost-of-poor-data-quality; https://www.bankofengland.co.uk/-/media/boe/files/prudential-regulation/regulatory-action/final-notice-from-pra-to-standard-chartered-bank.pdf; https://www.nysd.uscourts.gov/sites/default/files/2021-02/20cv6539%20Citibank%20Opinion.pdf; https://www.govinfo.gov/content/pkg/CHRG-113shrg80222/pdf/CHRG-113shrg80222.pdf] The only unresolved tension is granularity: the cost evidence is compelling but mostly records downstream manifestations of capability debt rather than a clean label of citizen development, so confidence on materiality is high while confidence on a single universal cost number remains medium.
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] There is no contradiction across the readiness frameworks because all of them imply that AI capability should be layered on top of stable governance, quality data, and controlled interfaces rather than used to compensate for their absence.

§5 Depth and Breadth Expansion

  • [fact; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf] Behavioural lens: workaround behaviour persists because it creates local productivity gains even when it creates enterprise-level control loss, which explains why bans that do not improve sanctioned delivery often fail.
  • [fact; source: https://www.theguardian.com/business/2021/dec/20/standard-chartered-fined-bank-of-england-pra; https://www.privacy.org.nz/assets/New-order/Resources-/Publications/Guidance-resources/OPC0003-Fact-Sheet-ENG2.pdf; https://www.pcisecuritystandards.org/document_library/] Regulatory lens: in regulated environments, the same workaround estate creates not only internal inefficiency but also reportability, privacy, and payment-security exposure, which raises the economic cost of leaving capability debt unresolved.
  • [fact; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://www.microsoft.com/en/customers/story/25909-heineken-microsoft-copilot-studio] Organisational-design lens: the evidence favours a platform-team and Center of Excellence operating model because it centralises standards and telemetry while decentralising low-risk solution building through controlled lanes.
  • [inference; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://docs.aws.amazon.com/bedrock/latest/userguide/security.html] Technical lens: the same maturity prerequisites that reduce citizen-development sprawl, identity, access control, sanctioned interfaces, auditability, and data quality, are also the prerequisites for safely granting agents write capability, so systems capability debt and agentic readiness are the same control problem viewed at different levels of automation.

§6 Synthesis

(This section seeds the Findings below.)

Executive summary:

[inference; source: https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://d-nb.info/1270139835/34; https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406).html] The reviewed evidence supports a strong but not monocausal claim that the working category used here as systems capability debt, meaning recurring gaps between operational demand and sanctioned system capability across integration, data quality, workflow timeliness, and delivery capacity, is the dominant recurring driver of citizen development sprawl in regulated enterprises, while low-code preference is mainly the enabling mechanism that absorbs unmet delivery demand. [fact; source: https://www.ibm.com/think/insights/cost-of-poor-data-quality; https://www.bankofengland.co.uk/-/media/boe/files/prudential-regulation/regulatory-action/final-notice-from-pra-to-standard-chartered-bank.pdf; https://www.nysd.uscourts.gov/sites/default/files/2021-02/20cv6539%20Citibank%20Opinion.pdf; https://www.govinfo.gov/content/pkg/CHRG-113shrg80222/pdf/CHRG-113shrg80222.pdf] Public quantified cost evidence shows that the operational-risk channels associated with that debt are already material, with organisations reporting more than USD 5 million annual losses from poor data quality and banking incidents ranging from a GBP 46.55 million fine to a mistaken USD 893 million payment and a USD 6.2 billion trading loss context involving spreadsheet-heavy controls. [inference; source: https://www.microsoft.com/en/customers/story/25909-heineken-microsoft-copilot-studio; https://learn.microsoft.com/en-us/power-platform/guidance/adoption/common-vision/establish-coe; https://learn.microsoft.com/en-us/power-platform/guidance/adoption/govern-at-scale] The governance architectures with the best public support do not suppress automation demand; they route it into tiered sanctioned lanes with telemetry, environment controls, DLP, shared pipelines, and central platform stewardship while simultaneously improving the underlying systems that created the workaround demand. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] No reviewed public framework provides a numeric readiness threshold for broad agentic autonomy, but all credible frameworks imply the same sequencing rule: capability remediation and platform control maturity must precede broad autonomous scope.

Key findings:

  1. High confidence. [inference; source: https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://d-nb.info/1270139835/34] The best available empirical evidence indicates that citizen development sprawl usually begins as a workaround response to slow, misaligned, or incomplete official systems rather than as an independent preference for low-code tools.
  2. High confidence. [fact; source: https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf] Shadow IT and Business-managed IT research repeatedly identifies Information Technology slowness, business-IT misalignment, and shortcomings in mandatory systems as the recurring conditions that produce local workaround estates.
  3. High confidence. [fact; source: https://www.ibm.com/think/insights/cost-of-poor-data-quality; https://www.bankofengland.co.uk/-/media/boe/files/prudential-regulation/regulatory-action/final-notice-from-pra-to-standard-chartered-bank.pdf; https://www.nysd.uscourts.gov/sites/default/files/2021-02/20cv6539%20Citibank%20Opinion.pdf; https://www.govinfo.gov/content/pkg/CHRG-113shrg80222/pdf/CHRG-113shrg80222.pdf] The operational-risk costs associated with capability-debt manifestations are already economically material in public evidence, even when the loss event is described as data quality, spreadsheet error, or legacy workflow failure rather than citizen development.
  4. Medium confidence. [inference; source: https://www.fdic.gov/media/168191; https://www.federalreserve.gov/econres/notes/feds-notes/operational-risk-regulation-forward-looking-and-sensitive-to-current-risks-20180521.html] Public banking-loss evidence is sufficient to show materiality but insufficient to produce a reliable universal cost coefficient for citizen-development sprawl because bank consortium data is sensitive and public sources overrepresent the largest failures.
  5. Medium confidence. [inference; source: https://www.microsoft.com/en/customers/story/25909-heineken-microsoft-copilot-studio; https://learn.microsoft.com/en-us/power-platform/guidance/adoption/common-vision/establish-coe; https://learn.microsoft.com/en-us/power-platform/guidance/adoption/govern-at-scale] The best-supported public governance pattern in the reviewed evidence is a tiered operating model with low-friction personal environments, formal promotion paths, shared and enterprise production lanes, central telemetry, and policy enforcement rather than a flat allow or deny regime.
  6. Medium confidence. [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/power-platform/guidance/coe/overview] The reviewed Microsoft governance and product documentation implies that durable citizen-development governance requires enforceable controls over authentication, knowledge sources, connectors, triggers, channels, telemetry, and lifecycle promotion, because telemetry without intervention points leaves risky estates visible but still executable.
  7. High confidence. [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] The same maturity gaps that create citizen-development sprawl also narrow the safe scope of agentic Artificial Intelligence because weak data, access controls, interfaces, and feedback loops are amplified by autonomous execution.
  8. Medium confidence. [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://learn.microsoft.com/en-us/power-platform/guidance/adoption/common-vision/establish-coe] A defensible risk-committee test for genuine AI value is whether the use case still creates material value after integration, data quality, workflow timeliness, and sanctioned automation are fixed, because use cases that fail that test are primarily capability-gap compensation.

Evidence map:

Claim Source Confidence Notes
[inference] The working category used here as systems capability debt, meaning recurring gaps between operational demand and sanctioned system capability, is the dominant recurring driver of citizen-development sprawl. Kopper et al. practitioner study; Klotz et al. literature review; Kass et al. low-code adoption review high Strong recurring pattern across workaround and low-code literature; the term itself is a synthesis label rather than a canonical published taxonomy.
[fact] Shadow IT studies repeatedly point to IT slowness, misalignment, and system shortcomings as workaround causes. Kopper et al. practitioner study; Klotz et al. literature review high Directly grounded in interview percentages and the literature-review taxonomy.
[fact] Capability-debt manifestations already create material public operational-risk costs. IBM poor-data-quality analysis; PRA final notice; Citibank Revlon opinion; US Senate JPMorgan record high Costs are public and concrete, but they are mostly downstream manifestations rather than explicitly tagged citizen-development events.
[inference] Public data shows materiality but not a universal cost coefficient for citizen-development sprawl. FDIC operational-loss paper; Federal Reserve operational-risk note medium Consortium and supervisory data exist, but public disclosure is limited and anonymised.
[inference] Tiered sanctioned lanes plus central telemetry are the best-supported public pattern for scaling maker demand while keeping governance workable. HEINEKEN customer story; Microsoft CoE guidance; Govern-at-scale guidance medium Support comes mainly from Microsoft guidance plus one measured Microsoft customer case, so the comparative judgment stays inferential.
[inference] The reviewed Microsoft governance material implies that enforceable controls over connectors, knowledge sources, triggers, and promotion paths are central to safe citizen-development governance. Copilot Studio security and governance; Copilot Studio DLP; CoE Starter Kit overview medium This is a prescriptive vendor-documentation inference rather than a comparative outcome study.
[inference] Capability maturity is a precondition for broad agentic scope. DORA 2025 report; NIST AI RMF Core; AWS agentic-security principles high Convergence across independent frameworks is strong, though no numeric threshold exists.
[inference] A useful AI-versus-capability-gap test is whether value survives after core remediation. DORA 2025 report; NIST AI RMF Core; Microsoft CoE guidance medium This is a synthesis rule, not a directly published named framework.

Assumptions:

  • Assumption: [assumption; source: https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://www.microsoft.com/en/customers/story/25909-heineken-microsoft-copilot-studio] Shadow IT, Business-managed IT, and large-enterprise Power Platform evidence is directionally applicable to regulated banking citizen development. Justification: direct bank-specific public case evidence is sparse, but the causal and governance mechanisms are organisational and platform patterns rather than bank-only technical patterns.

Analysis:

[fact; source: https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf] The causal claim was weighted most heavily toward the Shadow IT and Business-managed IT evidence because those sources directly investigate why unsanctioned or semi-sanctioned technology emerges inside organisations. [fact; source: https://d-nb.info/1270139835/34; https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406).html; https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6] Low-code studies were then used to test whether the evidence pointed instead to tool preference, and they did not displace the workaround explanation because they still describe pressure for faster, cheaper delivery under constrained engineering supply. [fact; source: https://www.ibm.com/think/insights/cost-of-poor-data-quality; https://www.bankofengland.co.uk/-/media/boe/files/prudential-regulation/regulatory-action/final-notice-from-pra-to-standard-chartered-bank.pdf; https://www.nysd.uscourts.gov/sites/default/files/2021-02/20cv6539%20Citibank%20Opinion.pdf; https://www.govinfo.gov/content/pkg/CHRG-113shrg80222/pdf/CHRG-113shrg80222.pdf] Cost evidence was treated as channel evidence rather than label evidence, because public losses are recorded as data, spreadsheet, reporting, or workflow failures even when they arise from the same underlying capability deficits that drive citizen-development workarounds. [inference; source: https://www.microsoft.com/en/customers/story/25909-heineken-microsoft-copilot-studio; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://learn.microsoft.com/en-us/power-platform/guidance/adoption/common-vision/establish-coe] Governance evidence was weighted toward architectures that preserve sanctioned speed, because the workaround literature and the HEINEKEN case both imply that durable control comes from combining guardrails with delivery capacity rather than from restriction alone.

Risks, gaps, uncertainties:

  • [fact; source: https://www.federalreserve.gov/econres/notes/feds-notes/operational-risk-regulation-forward-looking-and-sensitive-to-current-risks-20180521.html] Public banking-loss data is incomplete, and the most granular consortium datasets, including ORX-style collections, are typically anonymised or inaccessible.
  • [inference; source: https://www.ibm.com/think/insights/cost-of-poor-data-quality; https://www.fdic.gov/media/168191] Quantified losses can be traced confidently to capability-debt manifestations, but not always to citizen development as a labelled category.
  • [fact; source: https://www.microsoft.com/en/customers/story/25909-heineken-microsoft-copilot-studio] Public governance case studies with clear before-and-after sprawl reduction counts are scarce, so the strongest evidence is measured scale under governance rather than precise reduction percentages.
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook] No public threshold model was found that converts readiness into a single score suitable for a board pack without further local judgment.

Open questions:

  • [inference; source: https://www.federalreserve.gov/econres/notes/feds-notes/operational-risk-regulation-forward-looking-and-sensitive-to-current-risks-20180521.html] Could a bank-specific internal loss study translate workaround-estate attributes, spreadsheets, local databases, manual reconciliations, and unsanctioned flows, into a more precise operational-risk cost coefficient?
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] Can a practical readiness scorecard be built from data quality, access control, approved-interface coverage, test automation, and platform maturity without creating false precision?
  • [inference; source: https://www.microsoft.com/en/customers/story/25909-heineken-microsoft-copilot-studio] Which measured outcomes from large Microsoft 365 estates would remain valid when transferred into a prudentially regulated banking environment with tighter write-permission constraints?

Output:

§7 Recursive Review

  • [fact; source: https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://www.ibm.com/think/insights/cost-of-poor-data-quality; https://www.microsoft.com/en/customers/story/25909-heineken-microsoft-copilot-studio] Every material conclusion in the synthesis is either tied to a source-backed fact or explicitly marked as an inference or assumption.
  • [fact; source: https://www.theguardian.com/business/2021/dec/20/standard-chartered-fined-bank-of-england-pra; https://www.nysd.uscourts.gov/sites/default/files/2021-02/20cv6539%20Citibank%20Opinion.pdf; https://www.govinfo.gov/content/pkg/CHRG-113shrg80222/pdf/CHRG-113shrg80222.pdf] Quantified cost claims were cross-checked against primary or quasi-primary public incident records and not left resting on secondary vendor summaries alone.
  • [fact; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] The readiness and sequencing argument remains inferential rather than directly published as a named framework, and that uncertainty is preserved explicitly rather than hidden.

Findings

Executive Summary

[inference; source: https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://d-nb.info/1270139835/34; https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406).html] The reviewed evidence supports a strong but not monocausal claim that the working category used here as systems capability debt, meaning recurring gaps between operational demand and sanctioned system capability across integration, data quality, workflow timeliness, and delivery capacity, is the dominant recurring driver of citizen development sprawl in regulated enterprises, while low-code preference is mainly the enabling mechanism that absorbs unmet delivery demand. [fact; source: https://www.ibm.com/think/insights/cost-of-poor-data-quality; https://www.bankofengland.co.uk/-/media/boe/files/prudential-regulation/regulatory-action/final-notice-from-pra-to-standard-chartered-bank.pdf; https://www.nysd.uscourts.gov/sites/default/files/2021-02/20cv6539%20Citibank%20Opinion.pdf; https://www.govinfo.gov/content/pkg/CHRG-113shrg80222/pdf/CHRG-113shrg80222.pdf] Public quantified cost evidence shows that the operational-risk channels associated with that debt are already material, with organisations reporting more than USD 5 million annual losses from poor data quality and banking incidents ranging from a GBP 46.55 million fine to a mistaken USD 893 million payment and a USD 6.2 billion trading loss context involving spreadsheet-heavy controls. [inference; source: https://www.microsoft.com/en/customers/story/25909-heineken-microsoft-copilot-studio; https://learn.microsoft.com/en-us/power-platform/guidance/adoption/common-vision/establish-coe; https://learn.microsoft.com/en-us/power-platform/guidance/adoption/govern-at-scale] The governance architectures with the best public support do not suppress automation demand; they route it into tiered sanctioned lanes with telemetry, environment controls, DLP, shared pipelines, and central platform stewardship while simultaneously improving the underlying systems that created the workaround demand. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] No reviewed public framework provides a numeric readiness threshold for broad agentic autonomy, but all credible frameworks imply the same sequencing rule: capability remediation and platform control maturity must precede broad autonomous scope.

Key Findings

  1. High confidence. [inference; source: https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://d-nb.info/1270139835/34] The best available empirical evidence indicates that citizen development sprawl usually begins as a workaround response to slow, misaligned, or incomplete official systems rather than as an independent preference for low-code tools.
  2. High confidence. [fact; source: https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf] Shadow IT and Business-managed IT research repeatedly identifies Information Technology slowness, business-IT misalignment, and shortcomings in mandatory systems as the recurring conditions that produce local workaround estates.
  3. High confidence. [fact; source: https://www.ibm.com/think/insights/cost-of-poor-data-quality; https://www.bankofengland.co.uk/-/media/boe/files/prudential-regulation/regulatory-action/final-notice-from-pra-to-standard-chartered-bank.pdf; https://www.nysd.uscourts.gov/sites/default/files/2021-02/20cv6539%20Citibank%20Opinion.pdf; https://www.govinfo.gov/content/pkg/CHRG-113shrg80222/pdf/CHRG-113shrg80222.pdf] The operational-risk costs associated with capability-debt manifestations are already economically material in public evidence, even when the loss event is described as data quality, spreadsheet error, or legacy workflow failure rather than citizen development.
  4. Medium confidence. [inference; source: https://www.fdic.gov/media/168191; https://www.federalreserve.gov/econres/notes/feds-notes/operational-risk-regulation-forward-looking-and-sensitive-to-current-risks-20180521.html] Public banking-loss evidence is sufficient to show materiality but insufficient to produce a reliable universal cost coefficient for citizen-development sprawl because bank consortium data is sensitive and public sources overrepresent the largest failures.
  5. Medium confidence. [inference; source: https://www.microsoft.com/en/customers/story/25909-heineken-microsoft-copilot-studio; https://learn.microsoft.com/en-us/power-platform/guidance/adoption/common-vision/establish-coe; https://learn.microsoft.com/en-us/power-platform/guidance/adoption/govern-at-scale] The best-supported public governance pattern in the reviewed evidence is a tiered operating model with low-friction personal environments, formal promotion paths, shared and enterprise production lanes, central telemetry, and policy enforcement rather than a flat allow or deny regime.
  6. Medium confidence. [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/power-platform/guidance/coe/overview] The reviewed Microsoft governance and product documentation implies that durable citizen-development governance requires enforceable controls over authentication, knowledge sources, connectors, triggers, channels, telemetry, and lifecycle promotion, because telemetry without intervention points leaves risky estates visible but still executable.
  7. High confidence. [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] The same maturity gaps that create citizen-development sprawl also narrow the safe scope of agentic AI because weak data, access controls, interfaces, and feedback loops are amplified by autonomous execution.
  8. Medium confidence. [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://learn.microsoft.com/en-us/power-platform/guidance/adoption/common-vision/establish-coe] A defensible risk-committee test for genuine AI value is whether the use case still creates material value after integration, data quality, workflow timeliness, and sanctioned automation are fixed, because use cases that fail that test are primarily capability-gap compensation.

Evidence Map

Claim Source Confidence Notes
[inference] The working category used here as systems capability debt, meaning recurring gaps between operational demand and sanctioned system capability, is the dominant recurring driver of citizen-development sprawl. Kopper et al. practitioner study; Klotz et al. literature review; Kass et al. low-code adoption review high Strong recurring pattern across workaround and low-code literature; the term itself is a synthesis label rather than a canonical published taxonomy.
[fact] Shadow IT studies repeatedly point to IT slowness, misalignment, and system shortcomings as workaround causes. Kopper et al. practitioner study; Klotz et al. literature review high Directly grounded in interview percentages and the literature-review taxonomy.
[fact] Capability-debt manifestations already create material public operational-risk costs. IBM poor-data-quality analysis; PRA final notice; Citibank Revlon opinion; US Senate JPMorgan record high Costs are public and concrete, but they are mostly downstream manifestations rather than explicitly tagged citizen-development events.
[inference] Public data shows materiality but not a universal cost coefficient for citizen-development sprawl. FDIC operational-loss paper; Federal Reserve operational-risk note medium Consortium and supervisory data exist, but public disclosure is limited and anonymised.
[inference] Tiered sanctioned lanes plus central telemetry are the best-supported public pattern for scaling maker demand while keeping governance workable. HEINEKEN customer story; Microsoft CoE guidance; Govern-at-scale guidance medium Support comes mainly from Microsoft guidance plus one measured Microsoft customer case, so the comparative judgment stays inferential.
[inference] The reviewed Microsoft governance material implies that enforceable controls over connectors, knowledge sources, triggers, and promotion paths are central to safe citizen-development governance. Copilot Studio security and governance; Copilot Studio DLP; CoE Starter Kit overview medium This is a prescriptive vendor-documentation inference rather than a comparative outcome study.
[inference] Capability maturity is a precondition for broad agentic scope. DORA 2025 report; NIST AI RMF Core; AWS agentic-security principles high Convergence across independent frameworks is strong, though no numeric threshold exists.
[inference] A useful AI-versus-capability-gap test is whether value survives after core remediation. DORA 2025 report; NIST AI RMF Core; Microsoft CoE guidance medium This is a synthesis rule, not a directly published named framework.

Assumptions

  • Assumption: [assumption; source: https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://www.microsoft.com/en/customers/story/25909-heineken-microsoft-copilot-studio] Shadow IT, Business-managed IT, and large-enterprise Power Platform evidence is directionally applicable to regulated banking citizen development. Justification: direct bank-specific public case evidence is sparse, but the causal and governance mechanisms are organisational and platform patterns rather than bank-only technical patterns.

Analysis

[fact; source: https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf] The causal claim was weighted most heavily toward the Shadow IT and Business-managed IT evidence because those sources directly investigate why unsanctioned or semi-sanctioned technology emerges inside organisations. [fact; source: https://d-nb.info/1270139835/34; https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406).html; https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6] Low-code studies were then used to test whether the evidence pointed instead to tool preference, and they did not displace the workaround explanation because they still describe pressure for faster, cheaper delivery under constrained engineering supply. [fact; source: https://www.ibm.com/think/insights/cost-of-poor-data-quality; https://www.bankofengland.co.uk/-/media/boe/files/prudential-regulation/regulatory-action/final-notice-from-pra-to-standard-chartered-bank.pdf; https://www.nysd.uscourts.gov/sites/default/files/2021-02/20cv6539%20Citibank%20Opinion.pdf; https://www.govinfo.gov/content/pkg/CHRG-113shrg80222/pdf/CHRG-113shrg80222.pdf] Cost evidence was treated as channel evidence rather than label evidence, because public losses are recorded as data, spreadsheet, reporting, or workflow failures even when they arise from the same underlying capability deficits that drive citizen-development workarounds. [inference; source: https://www.microsoft.com/en/customers/story/25909-heineken-microsoft-copilot-studio; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://learn.microsoft.com/en-us/power-platform/guidance/adoption/common-vision/establish-coe] Governance evidence was weighted toward architectures that preserve sanctioned speed, because the workaround literature and the HEINEKEN case both imply that durable control comes from combining guardrails with delivery capacity rather than from restriction alone.

Risks, Gaps, and Uncertainties

  • [fact; source: https://www.federalreserve.gov/econres/notes/feds-notes/operational-risk-regulation-forward-looking-and-sensitive-to-current-risks-20180521.html] Public banking-loss data is incomplete, and the most granular consortium datasets, including ORX-style collections, are typically anonymised or inaccessible.
  • [inference; source: https://www.ibm.com/think/insights/cost-of-poor-data-quality; https://www.fdic.gov/media/168191] Quantified losses can be traced confidently to capability-debt manifestations, but not always to citizen development as a labelled category.
  • [fact; source: https://www.microsoft.com/en/customers/story/25909-heineken-microsoft-copilot-studio] Public governance case studies with clear before-and-after sprawl reduction counts are scarce, so the strongest evidence is measured scale under governance rather than precise reduction percentages.
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook] No public threshold model was found that converts readiness into a single score suitable for a board pack without further local judgment.

Open Questions

  • [inference; source: https://www.federalreserve.gov/econres/notes/feds-notes/operational-risk-regulation-forward-looking-and-sensitive-to-current-risks-20180521.html] Could a bank-specific internal loss study translate workaround-estate attributes, spreadsheets, local databases, manual reconciliations, and unsanctioned flows, into a more precise operational-risk cost coefficient?
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] Can a practical readiness scorecard be built from data quality, access control, approved-interface coverage, test automation, and platform maturity without creating false precision?
  • [inference; source: https://www.microsoft.com/en/customers/story/25909-heineken-microsoft-copilot-studio] Which measured outcomes from large Microsoft 365 estates would remain valid when transferred into a prudentially regulated banking environment with tighter write-permission constraints?

Output


Output

Navigation

Home

By Tag

bureaucracy

change-management

coase

constraint-analysis

control-model

decision-rights

delegation

delivery-risk

demand-segmentation

enterprise

exception-handling

execution

flow

flow-design

flow-metrics

governance

governance-patterns

incentives

instability

institutional-economics

leading-indicators

operating-model

organisation

organisational-design

queue-design

queueing

regulated-enterprise

routing

throughput

throughput-risk

transaction-costs

triage

williamson

Clone this wiki locally